OpenSourceFellows / amplify-back-end

The API backend for ProgramEquity
https://www.programequity.com/
MIT License
10 stars 0 forks source link

Secure 'Check formatting' action #199

Closed manishapriya94 closed 2 years ago

Lehcar commented 2 years ago

I'm going to take a look at this (if anyone wants to join)

manishapriya94 commented 2 years ago

@Lehcar want to pair? its supposed to be an audit like this one: https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions

Lehcar commented 2 years ago

@Lehcar want to pair? its supposed to be an audit like this one: https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions

yes please! I messaged you on slack

Lehcar commented 2 years ago

I checked this workflow and it looks good 🎉 ! We're not currently using any secrets for the Check formatting workflow and we aren't doing any sort of script execution/injection in any of the running scripts.